İçeriğe atla
Noroxi

NukeViet kayıtları

nukeviet üreticisine ait 13 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%53,8
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

13 kayıt
  • CVE-2019-7725
    40Planlayın

    includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serializat

    KritikCVSS 9,8İstismar yokEPSS %3

    nukeviet · nukeviet31 Ara 2020

  • CVE-2019-7726
    40Planlayın

    modules/banners/funcs/click.php in NukeViet before 4.3.04 has a SQL INSERT statement with raw header data from an HTTP request (e.g., Refere

    KritikCVSS 9,8İstismar yokEPSS %2

    nukeviet · nukeviet31 Ara 2020

  • CVE-2020-21808
    39İzleyin

    SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics.php.

    KritikCVSS 9,8İstismar yokEPSS %2

    nukeviet · nukeviet30 Tem 2021

  • CVE-2020-21809
    39İzleyin

    SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price o

    KritikCVSS 9,8İstismar yokEPSS %2

    nukeviet · nukeviet30 Tem 2021

  • CVE-2024-36528
    35İzleyin

    nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /ad

    YüksekCVSS 8,8İstismar yokEPSS %1

    nukeviet · egovernment10 Haz 2024

  • CVE-2020-13155
    35İzleyin

    clearsystem.php in NukeViet 4.4 allows CSRF with resultant HTML injection via the deltype parameter to the admin/index.php?nv=webtools&op=cl

    YüksekCVSS 8,8İstismar yokEPSS %1

    nukeviet · nukeviet23 Haz 2020

  • CVE-2020-13157
    26İzleyin

    modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=edit&userid= URI.

    OrtaCVSS 6,5İstismar yokEPSS %1

    nukeviet · nukeviet23 Haz 2020

  • CVE-2020-13156
    26İzleyin

    modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.

    OrtaCVSS 6,5İstismar yokEPSS %1

    nukeviet · nukeviet23 Haz 2020

  • CVE-2020-22765
    24İzleyin

    Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module.

    OrtaCVSS 6,1İstismar yokEPSS %1

    nukeviet · nukeviet30 Tem 2021

  • CVE-2022-3975
    24İzleyin

    NukeViet CMS Data URL Request.php filterAttr cross site scripting

    OrtaCVSS 6,1İstismar yokEPSS %1

    nukeviet · nukeviet13 Kas 2022

  • CVE-2024-36531
    22İzleyin

    nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.

    OrtaCVSS 5,7İstismar yokEPSS %0

    nukeviet · egovernment10 Haz 2024

  • CVE-2022-30874
    21İzleyin

    There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.

    OrtaCVSS 5,4İstismar yokEPSS %1

    nukeviet · nukeviet21 Haz 2022

  • CVE-2025-8772
    8İzleyin

    Vinades NukeViet Module index.php server-side request forgery

    DüşükCVSS 2,1İstismar yokEPSS %0

    nukeviet · nukeviet9 Ağu 2025